Following the recent scandal around A level results day in England and Wales, in which almost 40% of students were downgraded through the use of an algorithm developed by exams regulator Ofqual (due to Covid-19 disrupting exams), the ICO (Information Commissioner’s Office) has come under quite a bit of fire. Now the head of Ofqual, Sally Collier, is being forced to resign over the fiasco and once again the ICO appears to slip away from another disaster completely blameless.

Who are the ICO? Well to keep it short and sweet for those who do know, the ICO is a non-departmental public body that reports directly to the Department of Culture, Media and Sport. Their primary role is to enforce data protection law (amongst other related law), the main controversy around them recently being that, well, they haven’t been doing so, at least not effectively.

The exam debacle is just one example of this. Both GDPR and the Data Protection Act (2018) contain specific provisions applying to algorithms (creating automated decisions) that involve processing personal data. These provisions should’ve been enforced by the ICO and carried out before the government proceeded to use any type of algorithm.

It’s almost as if they didn’t want anybody to investigate an algorithm that would rather obviously have a massive significant effect on the students (aside of the apparent issue of favouring students in private education over the public sector). But surely the ICO must not have been aware of the risks in using algorithms in this instance? Wrong!  The ICO is very much aware of it, and have actually referred to the risk in using algorithms before and even last month published guidance on AI and data protection. Remarkably (as shown with the statement further down, the ICO has accepted the Ofqal statement that the grades are decided by a combination of Teacher assessment and the algorithm, therefore negating the condition that this is a fully automated decision. Most people would assert there are 2 stages to the decision, one of which is fully automated and has significant effects?)

Unfortunately, this event is not a one-off. It seems that the ICO suffers from recurring amnesia regarding its own purpose, this is triggered whenever it’s faced with ensuring the British government complies with GDPR law. Recently, the ICO sat on its hands and watched on as the government failed to perform a legally required DPIA (Data Protection Impact Assessment) prior to the launch of their Covid-19 Test and Trace program. This led to a cross-party group of MPs writing to the ICO stating that they need to begin holding the government responsible for data protection lapses.

Furthermore, this is made more frustrating when one sees that the head of the ICO, Elizabeth Denham, isn’t even working from within the UK. Yes, Denham since June has been operating from home in Canada, a time zone that’s 8 hours behind the UK which the ICO insists in no way impacts its operation. It needs to be said that Denham did leave on compassionate grounds to look after her ill mother, however, these recent issues only serve to highlight that if Denham’s absence from the UK isn’t impacting the ICO, something else certainly appears to be.

Prior to the U-turn the ICO released the following statement:

“Ofqual has stated that automated decision-making does not take place when the standardisation model is applied, and that teachers and exam board officers are involved in decisions on calculated grades. Anyone with any concerns about how their data has been handled should raise those concerns with the exam boards first, then report to us if they are not satisfied.

The spokesperson added: “The ICO will continue to monitor the situation and engage with Ofqual.”

“There is something rotten at the heart of the ICO that makes them tolerate government’s unlawful behaviour. The ICO is a public body, funded by the taxpayers, and accountable to parliament. They must now sit up, listen and act. As a regulator ICO must ensure that the government upholds the law.” – Jill Killock of the Open rights group.

Fortunately, common sese prevailed with the future of almost half of the UK’s current A-Level graduates hanging in the balance, the Government performed a U-turn and removed the algorithm.

Ofqual stated no automated decision making, and the ICO echoed that comment, however, neither has provided any rationale behind that. It is clear from their algorithm that the kind of standardisation they applied this year was precisely an automated decision: school/college provides assessed grades, but for larger cohorts, these were discarded and only the pupil ranking was used. Nevertheless, the point of whether the decision was automated or not the only issue; qualifications are personal data, therefore, the fact that transparency, fairness and accuracy all appear to have been ignored is arguably the main issue given that this is the first principle of GDPR.

Whatever your views on the ICO or the government may be, the fact remains that our UK government just attempted to use an algorithm, that is potentially unlawful, to decide the future of thousands of students around the UK and that they didn’t apply the first principle of the law. That, however you look at it, is a problem that needs addressing and the ICO has a responsibility to do so.

It’s difficult to imagine that further similar issues will be raised, and there is little confidence the ICO will stand up and be counted. Perhaps the very nature of the funding of the ICO (who employ over 800 staff) is a concern, can they be truly independent?

Unsure on GDPR and data protection law? Get in contact to learn more about your risks of and what your obligations are…